EPISODE · Dec 3, 2018 · 30 MIN
Jim Manico -- The Extremely Unabridged History of SQLi and XSS
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Why are SQL injection and cross-site scripting still with us after years of knowing how to prevent them? Jim Manico joins Chris for an informal journey through the history of both vulnerability classes and the defenses that changed application development. They discuss parameterized database APIs, output encoding, sanitization, framework defaults, and the long life of legacy software. The conversation then turns toward the future: what security libraries and language-specific analysis can do, where commercial testing tools fit, and who has an incentive to invest in stronger platforms. Jim’s recollections and predictions make this an opinionated archive conversation about progress and persistence, with a central challenge for developers and security teams: make protection a normal part of building software.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jim Manico:→ Jim Manico on LinkedInMentioned in this episode:→ DOMPurify→ OWASP ESAPI→ Go html/template→ Brakeman→ OWASP Top 10Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The history of SQL injection and XSS with Jim Manico01:33 How application security has changed05:06 Parameterized queries and early defenses07:20 Why injection remains on the Top 1009:22 Could SQL injection disappear?10:39 Tracing the history of cross-site scripting17:21 Carrying secure defaults into new frameworks19:34 Legacy applications and long software lifespans20:47 The role of defensive technology23:13 What happens to the security tool market?24:52 Why language-specific analysis matters26:26 Who pays for more secure platforms?
Embed this episode
What this episode covers
Why are SQL injection and cross-site scripting still with us after years of knowing how to prevent them? Jim Manico joins Chris for an informal journey through the history of both vulnerability classes and the defenses that changed application development. They discuss parameterized database APIs, output encoding, sanitization, framework defaults, and the long life of legacy software. The conversation then turns toward the future: what security libraries and language-specific analysis can do,...
Ready to play
Jim Manico -- The Extremely Unabridged History of SQLi and XSS
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.